
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-40057 is a vulnerability discovered in the Linux kernel's PTP (Precision Time Protocol) implementation, reported by syzbot and disclosed on October 28, 2025. The vulnerability affects the maxvclocksstore functionality when the argument max is too large for kcalloc to handle (NVD).
The vulnerability occurs in the Linux kernel's PTP subsystem when handling max_vclocks values. Specifically, the issue arises when the argument max is too large for the kcalloc function to handle properly, requiring an extension of the guard to prevent values that exceed kcalloc's capacity (NVD, Ubuntu).
The vulnerability affects multiple Linux distributions and kernel versions, with Ubuntu assigning it a Medium priority. Several kernel versions across different distributions are marked as vulnerable, including Ubuntu 24.04 LTS noble and 22.04 LTS jammy in various configurations (Ubuntu).
The vulnerability has been resolved through patches in various Linux kernel versions. Some distributions have already implemented fixes, while others are marked as not affected or have superseded the vulnerable versions with updated kernel releases (Ubuntu, Debian).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."